PT-2012-6318 · Libssh+1 · Libssh+1

Florian Weimer

·

Published

1970-01-01

·

Updated

2017-08-29

·

CVE-2012-4562

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libssh versions prior to 0.5.3
Description The issue affects the libssh package, allowing remote attackers to exploit multiple integer overflows, which can lead to a denial of service or possibly execute arbitrary code. This can result in a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations For versions prior to 0.5.3, update to version 0.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the libssh package until a patch is available.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02019
BDU:2015-04569
BDU:2015-09720
CVE-2012-4562
DSA-2577-1
OPENSUSE-SU-2012_1620-1
SUSE-SU-2012_1520-1

Affected Products

Suse
Libssh